Skip to content

[RFC] Security: 12 vulnerabilities (critical) #8

Description

@git-steer

RFC: Security Vulnerability Remediation

Repository: ry-ops/unifi-mcp-server
Severity: CRITICAL
Date: 2026-02-15
Generated by: git-steer autonomous security sweep

Vulnerabilities

CVE Package Severity Current Fix Version
CVE-2026-21441 urllib3 HIGH >= 1.22, < 2.6.3 2.6.3
CVE-2025-66471 urllib3 HIGH >= 1.0, < 2.6.0 2.6.0
CVE-2025-66418 urllib3 HIGH >= 1.24, < 2.6.0 2.6.0
CVE-2025-66416 mcp HIGH < 1.23.0 1.23.0
CVE-2025-62727 starlette HIGH >= 0.39.0, <= 0.49.0 0.49.1
CVE-2025-54121 starlette MEDIUM < 0.47.2 0.47.2
CVE-2025-53366 mcp HIGH < 1.9.4 1.9.4
CVE-2025-53365 mcp HIGH < 1.10.0 1.10.0
CVE-2025-50182 urllib3 MEDIUM >= 2.2.0, < 2.5.0 2.5.0
CVE-2025-50181 urllib3 MEDIUM < 2.5.0 2.5.0
CVE-2024-47081 requests MEDIUM < 2.32.4 2.32.4
CVE-2025-43859 h11 CRITICAL < 0.16.0 0.16.0

Code Scanning Alerts

Rule Severity File Line
actions/unpinned-tag medium .github/workflows/docker-build-push.yml 64
actions/unpinned-tag medium .github/workflows/docker-build-push.yml 50
actions/unpinned-tag medium .github/workflows/docker-build-push.yml 42
actions/unpinned-tag medium .github/workflows/claude.yml 31
actions/unpinned-tag medium .github/workflows/docker-build-push.yml 39

Change Plan

  1. Update vulnerable dependencies to patched versions
  2. Run automated tests to verify compatibility
  3. Create PR with fixes
  4. Merge after review

Risk Assessment

  • Impact of not fixing: Potential security breach via known CVEs
  • Impact of fix: Dependency version bumps, low risk of breakage
  • Rollback plan: Revert PR if tests fail

This RFC was auto-generated by git-steer. A fix PR will be created automatically.

Metadata

Metadata

Assignees

Labels

automatedCreated by automationrfcRequest for ChangesecuritySecurity vulnerabilityseverity:criticalcritical severity

Projects

No projects

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions